Back

Privacy Policy for CocoViral

Effective date: October 6, 2026

1. Who we are

CocoViral (https://www.cocoviral.ai) is an AI video and image creation platform. You use it to generate images and videos from text and reference media, clone and remix viral videos, translate and localize videos, and organize the results in your library. CocoViral also offers an API, a command-line tool, and connectors for AI assistants such as ChatGPT and Claude.

This policy explains what data CocoViral collects, why, who it is shared with, how long it is kept, and the choices you have. It applies to the website, the API, the CLI and the assistant connectors. Questions go to [email protected].

2. Data we collect

We collect only what we need to run the service:

  • Account data: your email address and, if you provide it, your name and profile picture. If you sign in with Google or Apple, we receive these from that provider (see section 3).
  • Content you provide: prompts, scripts, links to videos you ask us to analyze, and images, videos and audio you upload as references.
  • Content we generate for you: images, videos, audio and analyses, together with the settings used to create them.
  • Billing data: your plan, credit balance and purchase history. Card details are entered on and stored by Stripe; we never see or store full card numbers.
  • Technical and usage data: IP address, browser and device type, pages visited, features used, and error logs, collected with cookies and similar technologies.
  • Integration data: API keys you create (we store only a hash), and the authorization records for apps you connect, such as ChatGPT or Claude.
  • Communications: messages you send to support and your email preferences.

3. Google user data

When you choose "Continue with Google", CocoViral uses Google Sign-In and requests only these basic scopes: openid, email and profile. We do not request access to your Gmail, Google Drive, YouTube, Calendar, Contacts or any other Google service.

Data accessed: your Google account identifier, email address, name and profile picture.

How we use it:

  • To create your CocoViral account, sign you in, and keep your account secure.
  • To show your name and picture in your account and to contact you about your account, purchases and service changes.

How we store and protect it: this data is stored in our authentication database (hosted by Supabase), encrypted in transit and at rest, and accessible only to systems and staff who need it to operate the service.

How we share it: we do not sell Google user data, use it for advertising, or transfer it to third parties, except to the service providers that host and operate our platform on our behalf (section 5), or when required by law.

AI models: we do not use Google user data to develop, improve or train generalized AI or machine learning models.

Retention and deletion: we keep this data while your account exists. When you delete your account (section 8), we delete it within 30 days. You can also revoke our access at any time at https://myaccount.google.com/permissions.

CocoViral's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

4. How we use your data

  • To provide the service: run your generations, store your results, and show them in your library.
  • To process payments and manage subscriptions and credits.
  • To secure the service: authenticate you, prevent fraud and abuse, and enforce our Terms.
  • To support you and send service messages, such as receipts, security notices and changes to these terms.
  • To send product news, if you have not opted out. Every marketing email has an unsubscribe link.
  • To understand and improve the product with aggregated usage analytics.

We do not sell your personal data, and we do not use your uploads or generated content to train our own AI models.

5. Who we share data with

We share data only with providers that help us run the service, under contracts that limit their use of it to that purpose:

  • Hosting and infrastructure: Railway (application hosting), Supabase (database and authentication), Cloudflare (CDN, DNS and file storage).
  • AI model providers: when you generate or analyze media, your prompt and reference media are sent to the model provider you chose or that the feature uses (for example OpenAI, Google, Anthropic, ByteDance, MiniMax, Kuaishou, Black Forest Labs, Midjourney) and the platforms that serve them (for example fal.ai and Replicate). They process it to return the result.
  • Payments: Stripe.
  • Email delivery: Resend and Google Workspace.
  • Analytics and attribution: PostHog, Google Analytics, Plausible, DataFast and Rewardful (for referral partners).
  • Apps you connect: when you connect ChatGPT, Claude or another assistant, that app receives the results of the actions you ask it to take.

We may also disclose data if required by law, to protect our users or the service, or as part of a merger or acquisition, in which case this policy continues to apply.

6. Cookies

We use cookies and local storage to keep you signed in, remember your preferences, measure how the product is used, and attribute sign-ups to marketing campaigns and referral partners. You can block or delete cookies in your browser settings; the site may not work correctly without the cookies needed for sign-in.

7. Retention

  • Account data, Google user data and your content: kept while your account exists and deleted within 30 days of account deletion.
  • Billing records: kept as long as tax and accounting law requires.
  • Server logs: kept for up to 90 days.
  • Backups: deleted data may remain in encrypted backups for up to 30 more days before it is overwritten.

8. Your choices and rights

You can access, correct, export or delete your data. To delete your account and its data, or for any other request, email [email protected] from the address on your account. We respond within 30 days.

Depending on where you live (for example under the GDPR or California law), you may also have the right to object to or restrict processing, and to complain to your data protection authority.

You can disconnect Google Sign-In at https://myaccount.google.com/permissions, and disconnect assistant apps from their own settings.

9. Security

Data is encrypted in transit (HTTPS) and at rest. Access is limited to people and systems that need it, API keys are stored only as hashes, and payments are handled by Stripe. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.

10. International transfers

Our providers may process data in the United States and other countries. Where required, transfers rely on safeguards such as the European Commission's Standard Contractual Clauses.

11. Children

CocoViral is for people 18 and older, as our Terms of Service require. We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.

12. Changes to this policy

We will post changes on this page and update the effective date. If a change is significant, we will also notify you by email before it takes effect.

13. Contact

Privacy questions and requests: [email protected].